Skip to main content

How EMS is scored

The Exploitation Maturity Score (EMS) ranges from 0 to 10, reflecting the real-world exploitation evidence associated with a vulnerability, such as publicly available POCs and exploits, including their popularity and verification status. Stronger indicators such as weaponized exploits, known exploitation status, or confirmed use in ransomware campaigns have a higher influence on the score. A score of 0 means no exploitation activity has been confirmed by supported data sources. Higher scores indicate increasingly strong signals that attackers have enough information to weaponize and deploy the exploit, or that there is evidence of active exploitation in the wild. Even a single POC with strong popularity indicators, or multiple POCs and exploits combined, can reach a critical score of 8 before confirmation appears in any KEV list or exploit database. This reflects the increased public interest in the vulnerability, which is a powerful exploit maturity indicator, especially in the early days after disclosure. Scores from 0 to 8 scale linearly with exploitation evidence. EMS 8 corresponds to the critical exploitation threshold: a vulnerability confirmed to have enough evidence of exploitation maturity, which can be reached in various ways. Above 8, the score starts to use logarithmic normalization to increase the granularity for critical scored vulnerabilities, so only vulnerabilities with an exceptional combination of exploitation signals reach 9 or 10. This keeps EMS 10 rare and meaningful, reserved for the highest-priority threats. When two vulnerabilities have the same EMS, EPSS is used as a tiebreaker.

What is EMS Escalation

Our Exploitation Maturity Scoring (EMS) system tracks several key indicators of increased risk. When a vulnerability is associated with any of the following, it triggers an EMS Escalation:
  1. Ransomware: This escalation indicates that the vulnerability is known to be actively exploited by ransomware groups.
  2. CISA KEV (Known Exploited Vulnerabilities Catalog): This escalation signifies that the vulnerability has been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) KEV catalog. The KEV catalog lists vulnerabilities that CISA has evidence of being actively exploited in the wild.
  3. POCs (Proof of Concepts): This escalation is triggered when a proof-of-concept exploit for the vulnerability becomes publicly available. A POC demonstrates that the vulnerability can be exploited, even if it’s not yet used in widespread attacks.
  4. Public Exploits: This escalation indicates that functional exploit code for the vulnerability has been released publicly. This is a step beyond a POC, often meaning the exploit is more refined or easier to use.
  5. Weaponized Exploits: This is the highest level of EMS Escalation, indicating that the vulnerability is not only being actively exploited but is also part of known attack tools or malware campaigns. This means the exploit has been integrated into a “weapon” used by attackers.
You can read more about Exploitation Maturity Scoring (EMS) in Binarly Blog.

Where to view EMS Escalations

  1. Chronological Event Tracking: To see a detailed, time-ordered list of EMS Escalation events for a specific image, navigate to the Image Overview page. Within this page, you will find an Escalations tab that provides a chronological history of all exploitation maturity changes.
  1. Threat Intelligence Monitoring Widget: This widget can be found on the global dashboard and Image Overview and shows top 10 (by EMS Score) most pressing vulnerabilities present within the platform.

Notifications for EMS Escalations

To ensure you are promptly informed of EMS escalations, you can subscribe to Products to receive the Notifications.